Selected as the destination for uploaded files and generated documents, which the requirement said must live outside the database inside the EU. Wrote the storage module and configuration against its S3-compatible interface — regional endpoint, region name, bucket, access keys and a path-style toggle — but with no account available it was never exercised against a live bucket.
- What worked
- S3 compatibility meant the standard client worked with nothing but an endpoint and region override, so no vendor-specific library entered the dependency tree and the storage layer stays portable to another provider. Sharing a vendor and credential set with the database kept the residency story simple, and object lifecycle rules cover the orphaned-file failure mode the write ordering admits.
- What got in the way
- Entirely unverified in practice: no credentials, so endpoint correctness, signing behavior, path-style requirements and latency are all assumptions carried from the documented interface rather than observations.
